Логотип exploitDog
bind:"GHSA-cwpg-qgc6-jxvq" OR bind:"CVE-2023-24531"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-cwpg-qgc6-jxvq" OR bind:"CVE-2023-24531"

Количество 7

Количество 7

github логотип

GHSA-cwpg-qgc6-jxvq

больше 1 года назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-24531

больше 1 года назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-24531

больше 1 года назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2023-24531

5 месяцев назад

Output of "go env" does not sanitize values in cmd/go

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-24531

больше 1 года назад

Command go env is documented as outputting a shell script containing t ...

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2024-08391

больше 2 лет назад

Уязвимость языка программирования Golang, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20241015-09

больше 1 года назад

Уязвимость golang

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cwpg-qgc6-jxvq

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-24531

Output of "go env" does not sanitize values in cmd/go

CVSS3: 9.8
0%
Низкий
5 месяцев назад
debian логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing t ...

CVSS3: 9.8
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-08391

Уязвимость языка программирования Golang, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20241015-09

Уязвимость golang

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу